A rapidly evolving Android spyware campaign called ClayRat has targeted users in Russia using a mix of Telegram channels and lookalike phishing websites by impersonating popular apps like WhatsApp, Google Photos, TikTok, and YouTube as lures to install them. “Once active, the spyware can exfiltrate SMS messages, call logs, notifications, and device information; taking photos with the
Read MoreA research team at the University of California, Irvine (UCI) has uncovered a startling way to turn one of the most ordinary pieces of computer hardware, a mouse into a covert listening device. Not a member, read full article here: https://medium.com/tech-waves/your-gaming-mouse-could-be-spying-on-you-the-alarming-mic-e-mouse-ai-attack-that-listens-through-4f812b8dc6b3?sk=febd00cc6bae8f0b8f9b18c3e40d912c Their project, aptly named Mic-E-Mouse, demonstrates that the sensors in high-performance optical mice can pick up minute vibrations from a
Read MoreAdobe has warned of a critical security flaw in its Commerce and Magento Open Source platforms that, if successfully exploited, could allow attackers to take control of customer accounts. The vulnerability, tracked as CVE-2025-54236 (aka SessionReaper), carries a CVSS score of 9.1 out of a maximum of 10.0. It has been described as an improper input validation
Read MorePhishing-as-a-Service (PhaaS) platforms keep evolving, giving attackers faster and cheaper ways to break into corporate accounts. Now, researchers at ANY.RUN has uncovered a new entrant: Salty2FA, a phishing kit designed to bypass multiple two-factor authentication methods and slip past traditional defenses. Already spotted in campaigns across the US and EU, Salty2FA puts enterprises at risk by targeting industries
Read More